🟡 Medium  |  Source: GCP Compute Engine Security Bulletins


Three vulnerabilities in TianoCore EDK II UEFI firmware, used by Google Compute Engine VMs, could allow attackers to bypass Secure Boot and produce false measurements in the boot process — including on Shielded VMs. Google has already patched all affected VMs across Compute Engine, so no customer action is required. The CVEs (CVE-2022-36763, CVE-2022-36764, CVE-2022-36765) relate to the firmware layer beneath the operating system, making them particularly sensitive.

Security Architect’s Take: No immediate remediation is needed as Google has patched all Compute Engine VMs automatically. However, architects relying on Shielded VMs for firmware integrity assurances should review their Secure Boot attestation posture and consider whether firmware-level trust assumptions feature in their threat models or compliance obligations.

Original advisory: GCP-2024-001